NPD Validator
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The plugin's requirements, instructions, and files align with a multi‑agent product‑validation pipeline; nothing requests unrelated credentials or hidden network endpoints, but inspect the included install script and be mindful of the plugin's web access and file I/O.
This plugin appears internally consistent with its stated purpose. Before installing or running it: (1) review openclaw-install.sh — it will create workspace files on disk; only run it in a safe/isolated directory; (2) be aware the agents perform many web searches and use WebFetch/SubAgent and will read/write data/*.md — do not place secrets or unintended proprietary files in the plugin workspace; (3) the plugin does not request external credentials, but because it can autonomously spawn subagents and fetch web data, prefer running it in an environment without access to sensitive system-level files or hidden credentials; (4) if you need tighter controls, limit web access or run the skill in a sandboxed account/workspace.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
